<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX Context hairpinning in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-context-hairpinning/m-p/1621260#M595215</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can not see why there should be a hairpinning or U-turn. But since it is working fine from other sites, but not from the other context, then I begin to suspect that it could be something like this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Because we have 2 different webservers and it is the same issue with both of them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the setup is user-context1-context2-webserver&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Erik Jacobsen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 Jan 2011 20:07:42 GMT</pubDate>
    <dc:creator>Erik Jacobsen</dc:creator>
    <dc:date>2011-01-05T20:07:42Z</dc:date>
    <item>
      <title>PIX Context hairpinning</title>
      <link>https://community.cisco.com/t5/network-security/pix-context-hairpinning/m-p/1621258#M595202</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have 2 security context configured on at PIX 525 with 8.0.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Users on context 1 should be able to reach webservers on context 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can not see in any logs that the traffic is being blocked, but it is not possible to get to the page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From everywhere else it works fine from the internet, so the webservers are working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I ping from context 1 I get the right ip address of the webservers, so it does not look like a DNS issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the question is, even I'm using 2 context does the firewall see it as one, so it things I'm trying to do hairpinning?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or what can be the reason since it is blocking.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Erik Jacobsen&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:30:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-context-hairpinning/m-p/1621258#M595202</guid>
      <dc:creator>Erik Jacobsen</dc:creator>
      <dc:date>2019-03-11T19:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Context hairpinning</title>
      <link>https://community.cisco.com/t5/network-security/pix-context-hairpinning/m-p/1621259#M595210</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is this cascading contexts? or is there a layer-3 device in between?&lt;/P&gt;&lt;P&gt;What is the topology?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;source--ctx1--ctx2--server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;source--ctx1--router--ctx2--server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to watch the logs in both contexts for these IP addresses in question and see why it is failing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no U-Turning here that I can see.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jan 2011 15:42:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-context-hairpinning/m-p/1621259#M595210</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2011-01-05T15:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Context hairpinning</title>
      <link>https://community.cisco.com/t5/network-security/pix-context-hairpinning/m-p/1621260#M595215</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can not see why there should be a hairpinning or U-turn. But since it is working fine from other sites, but not from the other context, then I begin to suspect that it could be something like this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Because we have 2 different webservers and it is the same issue with both of them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the setup is user-context1-context2-webserver&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Erik Jacobsen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jan 2011 20:07:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-context-hairpinning/m-p/1621260#M595215</guid>
      <dc:creator>Erik Jacobsen</dc:creator>
      <dc:date>2011-01-05T20:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Context hairpinning</title>
      <link>https://community.cisco.com/t5/network-security/pix-context-hairpinning/m-p/1621261#M595220</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;PS. I have checked all Access-lists on both contexts and I there should not be anything blocking.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Erik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jan 2011 20:09:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-context-hairpinning/m-p/1621261#M595220</guid>
      <dc:creator>Erik Jacobsen</dc:creator>
      <dc:date>2011-01-05T20:09:03Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Context hairpinning</title>
      <link>https://community.cisco.com/t5/network-security/pix-context-hairpinning/m-p/1621262#M595222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why you dont just try to run a packet-tracer in both context. Tray to take some captures as well. Does the context 1 knows how to reach the server? are you permiting this traffic in context 2? can u post the configuration.... that would make the things easier.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jan 2011 15:48:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-context-hairpinning/m-p/1621262#M595222</guid>
      <dc:creator>Diego Armando Cambronero Arias</dc:creator>
      <dc:date>2011-01-06T15:48:30Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Context hairpinning</title>
      <link>https://community.cisco.com/t5/network-security/pix-context-hairpinning/m-p/1621263#M595227</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been running the packet tracer on both contexts, and both of them is saying the traffic should be allowed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My customer just told me that, it actually works some times.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So this is even more weird. Because normally it works or else it is blocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So we are looking a bit on his domain controllers, what have been changed here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also found out that I can not do a simply ssh to the firewall, only http and telnet works. Even it is configured correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the firewall will be scheduled a reboot tomorrow afternone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Erik Jacobsen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jan 2011 22:53:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-context-hairpinning/m-p/1621263#M595227</guid>
      <dc:creator>Erik Jacobsen</dc:creator>
      <dc:date>2011-01-06T22:53:00Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Context hairpinning</title>
      <link>https://community.cisco.com/t5/network-security/pix-context-hairpinning/m-p/1621264#M595230</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all your time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have now rebooted the pix 525, and now everything works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and then we found out the "standby" pix did not work, so even more issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have adviced the customer to change the pixes almost a year a go, to ASA firewalls. So maybe they soon will find the money &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Case closed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Erik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Jan 2011 10:41:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-context-hairpinning/m-p/1621264#M595230</guid>
      <dc:creator>Erik Jacobsen</dc:creator>
      <dc:date>2011-01-07T10:41:03Z</dc:date>
    </item>
  </channel>
</rss>

